How to get tidy updated in various distribution channels?
Geoff McLane <[email protected]> Mon, 28 Sep 2015 15:32:29 +0200
| Newsgroups | gmane.comp.web.html-tidy.user |
|---|---|
| Message-ID | <[email protected]> |
This is a multi-part message in MIME format. --------------070606030407000503040301 Content-Type: text/plain; charset=utf-8; format=flowed Content-Transfer-Encoding: 8bit Cross post this on the public list -------- Forwarded Message -------- Subject: How to get tidy updated in various distribution channels? Date: Mon, 28 Sep 2015 15:27:11 +0200 From: Geoff McLane <[email protected]> To: Edward Vielmetti <[email protected]>, Sierk Bornemann <[email protected]> CC: [email protected], Ryan Schmidt <[email protected]> Hi Sierk, As Edward points out, thanks largely to him, we have the Apple platform well covered, but it would be nice if Apple also weighed in ;=)) But there is a real problem with Ubuntu (Debian)! And probably LOTS of other package distributions... I just checked synaptic in my Ubuntu 14.04 LTS, and it still lists libtidy-0.99, circa 2009 ;=(( YUK!!! I checked around LaunchPad - https://launchpad.net/tidy - and found this still points to sourceforge 2009 tidy, home page and source! UGH! How do we change that? I do not fully understand how these things work, having not used them before... But maybe we should write to Curtis Hovey (maybe [email protected]?)? Direct approach... maybe cc him on this... Or maybe there is a way to file for a badly needed package update??? Where? And the page - https://launchpad.net/ubuntu/trusty/+source/tidy - also shows 2009 Tidy, despite the fact that an update (Ha!) was done 2015-07-23!!! Nearly a month after our 5.0.0 release... We certainly need to STIR something up somewhere ;=)) Important Links: site: http://www.html-tidy.org/ source: https://github.com/htacg/tidy-html5 binaries: http://www.htacg.org/binaries/ bugs: https://github.com/htacg/tidy-html5/issues list: https://lists.w3.org/Archives/Public/html-tidy/ api: http://www.htacg.org/tidy-html5/tidylib_api/ quickref: http://www.htacg.org/tidy-html5/quickref.html Regards, Geoff. On 26/09/15 01:41, Edward Vielmetti wrote: > Sierk - sure take my text and use it if it will help. > > My next desire is not so much for Apple to update tidy (since it's readily > available in Macports and fink and Homebrew that platform is OK). > But Debian has an ancient tidy and I think that's addressable > in finite time to improve at least to get tidy-html5 into `sid`. > > On Fri, Sep 25, 2015 at 5:52 PM, Sierk Bornemann <[email protected] > <mailto:[email protected]>> wrote: > > Hi Geoff, > hi Edward, > hi Ryan! > > Tidy is part of Apple’s Open Source stack Darwin and so part of > their OS X distribution since years [1] as well as part of iOS as > well as of their newest OS, watchOS. Unfortunately, it's a very > old version: > > OS X 10.10.5 (Yosemite) > $ tidy --version > HTML Tidy for Mac OS X released on 31 October 2006 - Apple Inc. > build 15.15 > > Latest security updates for iOS and watchOS contain updates for > tidy, concerning CVE-2015-5522 and CVE-2015-5523 vulnerabilities, > which are closed in Tidy 4.9.31 and later 5.x. > > Apples Tidy is very outdated, is an old version based on the last > available version on SourceForge, hasn’t changed and updated for > years, isn’t capable of HTML5. > Years ago, Nov 17 2008, I filed a bug "Update HTML Tidy and > TidyLib to the latest official version" in Apple’s internal bug > database on https://bugreport.apple.com/ and mirrored the bug for > transparency purpose on OpenRadar [3]. I updated the bug’s > information July 31 2014, reflecting that W3C had forked the dead > SF tidy project to give it new life and to urge Apple to please > update tidy. > So far no reaction, no update from Apple to their tidy. > Since then, I’ve not updated the bug’s description, to reflect the > new situation under HTACG’s umbrella, but want do so shortly. > > [1] http://www.opensource.apple.com/ > http://www.opensource.apple.com/source/tidy/ > http://www.apple.com/opensource/ > > [2] APPLE-SA-2015-09-16-1 iOS 9 > http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html > > tidy > Available for: iPhone 4s and later, > iPod touch (5th generation) and later, iPad 2 and later > Impact: Visiting a maliciously crafted website may lead to arbitrary > code execution > Description: A memory corruption issue existed in Tidy. This issues > was addressed through improved memory handling. > CVE-ID > CVE-2015-5522 : Fernando Munoz of NULLGroup.com > CVE-2015-5523 : Fernando Munoz of NULLGroup.com > > APPLE-SA-2015-09-21-1 watchOS 2 > http://lists.apple.com/archives/security-announce/2015/Sep/msg00005.html > > [quote] > tidy > Available for: Apple Watch Sport, Apple Watch, > and Apple Watch Edition > Impact: Visiting a maliciously crafted website may lead to arbitrary > code execution > Description: A memory corruption issue existed in Tidy. This issues > was addressed through improved memory handling. > CVE-ID > CVE-2015-5522 : Fernando Munoz of NULLGroup.com > CVE-2015-5523 : Fernando Munoz of NULLGroup.com > [/quote] > > [3] OpenRadar bug 6376494 (Apple internal rdar://6376494): Update > HTML Tidy and TidyLib to the latest official version > http://openradar.appspot.com/6376494 > > > > My question to you is: what can be done, what can you/we do, > beyond my past efforts in this case, to convince Apple to > eventually update its old outdated stock tidy to the most recent > stable one of HTACG? Any Idea? Any suggestions? > > @Edward Vielmetti: > May I take, with your allowance, just for convenience and instead > of writing my own text, your text of fink ticket #1044 > http://sourceforge.net/p/fink/package-requests/1044/ and copy it > for updating my Apple Rdar-bug 6376494 as well as its OpenRadar > equivalent? > > Suggestions and help welcome, > Regards, > Sierk Bornemann > > -- > Sierk Bornemann | web developer | germany > > -- > Edward Vielmetti +1 734 330 2465 > [email protected] <mailto:[email protected]> > --------------070606030407000503040301 Content-Type: text/html; charset=utf-8 Content-Transfer-Encoding: 8bit <html> <head> <meta http-equiv="content-type" content="text/html; charset=utf-8"> </head> <body text="#000000" bgcolor="#FFFFFF"> Cross post this on the public list<br> <div class="moz-forward-container"><br> -------- Forwarded Message -------- <table class="moz-email-headers-table" border="0" cellpadding="0" cellspacing="0"> <tbody> <tr> <th align="RIGHT" valign="BASELINE" nowrap="nowrap">Subject: </th> <td>How to get tidy updated in various distribution channels?</td> </tr> <tr> <th align="RIGHT" valign="BASELINE" nowrap="nowrap">Date: </th> <td>Mon, 28 Sep 2015 15:27:11 +0200</td> </tr> <tr> <th align="RIGHT" valign="BASELINE" nowrap="nowrap">From: </th> <td>Geoff McLane <a class="moz-txt-link-rfc2396E" href="mailto:[email protected]"><[email protected]></a></td> </tr> <tr> <th align="RIGHT" valign="BASELINE" nowrap="nowrap">To: </th> <td>Edward Vielmetti <a class="moz-txt-link-rfc2396E" href="mailto:[email protected]"><[email protected]></a>, Sierk Bornemann <a class="moz-txt-link-rfc2396E" href="mailto:[email protected]"><[email protected]></a></td> </tr> <tr> <th align="RIGHT" valign="BASELINE" nowrap="nowrap">CC: </th> <td><a class="moz-txt-link-abbreviated" href="mailto:[email protected]">[email protected]</a>, Ryan Schmidt <a class="moz-txt-link-rfc2396E" href="mailto:[email protected]"><[email protected]></a></td> </tr> </tbody> </table> <br> <br> <meta content="text/html; charset=utf-8" http-equiv="Content-Type"> Hi Sierk,<br> <br> As Edward points out, thanks largely to him, we have <br> the Apple platform well covered, but it would be nice <br> if Apple also weighed in ;=))<br> <br> But there is a real problem with Ubuntu (Debian)! And <br> probably LOTS of other package distributions...<br> <br> I just checked synaptic in my Ubuntu 14.04 LTS, and it <br> still lists libtidy-0.99, circa 2009 ;=(( YUK!!!<br> <br> I checked around LaunchPad - <a moz-do-not-send="true" class="moz-txt-link-freetext" href="https://launchpad.net/tidy">https://launchpad.net/tidy</a> - <br> and found this still points to sourceforge 2009 tidy, <br> home page and source! UGH!<br> <br> How do we change that? I do not fully understand how <br> these things work, having not used them before...<br> <br> But maybe we should write to Curtis Hovey (maybe <br> <a moz-do-not-send="true" class="moz-txt-link-abbreviated" href="mailto:[email protected]">[email protected]</a>?)? Direct approach... maybe cc <br> him on this...<br> <br> Or maybe there is a way to file for a badly needed<br> package update??? Where?<br> <br> And the page - <a moz-do-not-send="true" class="moz-txt-link-freetext" href="https://launchpad.net/ubuntu/trusty/+source/tidy">https://launchpad.net/ubuntu/trusty/+source/tidy</a> -<br> also shows 2009 Tidy, despite the fact that an update<br> (Ha!) was done 2015-07-23!!! Nearly a month after our<br> 5.0.0 release...<br> <br> We certainly need to STIR something up somewhere ;=))<br> <br> Important Links:<br> <br> site: <a moz-do-not-send="true" class="moz-txt-link-freetext" href="http://www.html-tidy.org/">http://www.html-tidy.org/</a><br> source: <a moz-do-not-send="true" class="moz-txt-link-freetext" href="https://github.com/htacg/tidy-html5">https://github.com/htacg/tidy-html5</a><br> binaries: <a moz-do-not-send="true" class="moz-txt-link-freetext" href="http://www.htacg.org/binaries/">http://www.htacg.org/binaries/</a><br> bugs: <a moz-do-not-send="true" class="moz-txt-link-freetext" href="https://github.com/htacg/tidy-html5/issues">https://github.com/htacg/tidy-html5/issues</a><br> list: <a moz-do-not-send="true" class="moz-txt-link-freetext" href="https://lists.w3.org/Archives/Public/html-tidy/">https://lists.w3.org/Archives/Public/html-tidy/</a><br> api: <a moz-do-not-send="true" class="moz-txt-link-freetext" href="http://www.htacg.org/tidy-html5/tidylib_api/">http://www.htacg.org/tidy-html5/tidylib_api/</a><br> quickref: <a moz-do-not-send="true" class="moz-txt-link-freetext" href="http://www.htacg.org/tidy-html5/quickref.html">http://www.htacg.org/tidy-html5/quickref.html</a><br> <br> Regards,<br> Geoff.<br> <br> <br> <div class="moz-cite-prefix">On 26/09/15 01:41, Edward Vielmetti wrote:<br> </div> <blockquote cite="mid:CAPRZce3DYpivPgRnOEdfn0eQA3jTC5jx3+KoaQf6kU=xuuWWSg@mail.gmail.com" type="cite"> <div dir="ltr">Sierk - sure take my text and use it if it will help. <div><br> </div> <div>My next desire is not so much for Apple to update tidy (since it's readily</div> <div>available in Macports and fink and Homebrew that platform is OK).</div> <div>But Debian has an ancient tidy and I think that's addressable</div> <div>in finite time to improve at least to get tidy-html5 into `sid`.</div> </div> <div class="gmail_extra"><br> <div class="gmail_quote">On Fri, Sep 25, 2015 at 5:52 PM, Sierk Bornemann <span dir="ltr"><<a moz-do-not-send="true" href="mailto:[email protected]" target="_blank"><a class="moz-txt-link-abbreviated" href="mailto:[email protected]">[email protected]</a></a>></span> wrote:<br> <blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">Hi Geoff,<br> hi Edward,<br> hi Ryan!<br> <br> Tidy is part of Apple’s Open Source stack Darwin and so part of their OS X distribution since years [1] as well as part of iOS as well as of their newest OS, watchOS. Unfortunately, it's a very old version:<br> <br> OS X 10.10.5 (Yosemite)<br> $ tidy --version<br> HTML Tidy for Mac OS X released on 31 October 2006 - Apple Inc. build 15.15<br> <br> Latest security updates for iOS and watchOS contain updates for tidy, concerning CVE-2015-5522 and CVE-2015-5523 vulnerabilities, which are closed in Tidy 4.9.31 and later 5.x.<br> <br> Apples Tidy is very outdated, is an old version based on the last available version on SourceForge, hasn’t changed and updated for years, isn’t capable of HTML5.<br> Years ago, Nov 17 2008, I filed a bug "Update HTML Tidy and TidyLib to the latest official version" in Apple’s internal bug database on <a moz-do-not-send="true" href="https://bugreport.apple.com/" rel="noreferrer" target="_blank">https://bugreport.apple.com/</a> and mirrored the bug for transparency purpose on OpenRadar [3]. I updated the bug’s information July 31 2014, reflecting that W3C had forked the dead SF tidy project to give it new life and to urge Apple to please update tidy.<br> So far no reaction, no update from Apple to their tidy.<br> Since then, I’ve not updated the bug’s description, to reflect the new situation under HTACG’s umbrella, but want do so shortly.<br> <br> [1] <a moz-do-not-send="true" href="http://www.opensource.apple.com/" rel="noreferrer" target="_blank">http://www.opensource.apple.com/</a><br> <a moz-do-not-send="true" href="http://www.opensource.apple.com/source/tidy/" rel="noreferrer" target="_blank">http://www.opensource.apple.com/source/tidy/</a><br> <a moz-do-not-send="true" href="http://www.apple.com/opensource/" rel="noreferrer" target="_blank">http://www.apple.com/opensource/</a><br> <br> [2] APPLE-SA-2015-09-16-1 iOS 9<br> <a moz-do-not-send="true" href="http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html" rel="noreferrer" target="_blank">http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html</a><br> <br> tidy<br> Available for: iPhone 4s and later,<br> iPod touch (5th generation) and later, iPad 2 and later<br> Impact: Visiting a maliciously crafted website may lead to arbitrary<br> code execution<br> Description: A memory corruption issue existed in Tidy. This issues<br> was addressed through improved memory handling.<br> CVE-ID<br> CVE-2015-5522 : Fernando Munoz of NULLGroup.com<br> CVE-2015-5523 : Fernando Munoz of NULLGroup.com<br> <br> APPLE-SA-2015-09-21-1 watchOS 2<br> <a moz-do-not-send="true" href="http://lists.apple.com/archives/security-announce/2015/Sep/msg00005.html" rel="noreferrer" target="_blank">http://lists.apple.com/archives/security-announce/2015/Sep/msg00005.html</a><br> <br> [quote]<br> tidy<br> Available for: Apple Watch Sport, Apple Watch,<br> and Apple Watch Edition<br> Impact: Visiting a maliciously crafted website may lead to arbitrary<br> code execution<br> Description: A memory corruption issue existed in Tidy. This issues<br> was addressed through improved memory handling.<br> CVE-ID<br> CVE-2015-5522 : Fernando Munoz of NULLGroup.com<br> CVE-2015-5523 : Fernando Munoz of NULLGroup.com<br> [/quote]<br> <br> [3] OpenRadar bug 6376494 (Apple internal rdar://6376494): Update HTML Tidy and TidyLib to the latest official version<br> <a moz-do-not-send="true" href="http://openradar.appspot.com/6376494" rel="noreferrer" target="_blank">http://openradar.appspot.com/6376494</a><br> <br> <br> <br> My question to you is: what can be done, what can you/we do, beyond my past efforts in this case, to convince Apple to eventually update its old outdated stock tidy to the most recent stable one of HTACG? Any Idea? Any suggestions?<br> <br> @Edward Vielmetti:<br> May I take, with your allowance, just for convenience and instead of writing my own text, your text of fink ticket #1044 <a moz-do-not-send="true" href="http://sourceforge.net/p/fink/package-requests/1044/" rel="noreferrer" target="_blank">http://sourceforge.net/p/fink/package-requests/1044/</a> and copy it for updating my Apple Rdar-bug 6376494 as well as its OpenRadar equivalent?<br> <br> Suggestions and help welcome,<br> Regards,<br> Sierk Bornemann<br> <br> --<br> Sierk Bornemann | web developer | germany<br> <br> </blockquote> </div> -- <br> <div class="gmail_signature">Edward Vielmetti +1 734 330 2465 <div><a moz-do-not-send="true" href="mailto:[email protected]" target="_blank">[email protected]</a></div> <div><br> </div> </div> </div> </blockquote> <br> <br> </div> <br> </body> </html> --------------070606030407000503040301--